Search CVE reports


Toggle filters

431 – 440 of 447 results


CVE-2018-21017

Low priority
Needs evaluation

GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.

2 affected packages

ccextractor, gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ccextractor Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
gpac Not in release Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-21016

Medium priority
Vulnerable

audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

2 affected packages

gpac, ccextractor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Vulnerable Vulnerable
ccextractor Not in release Needs evaluation Vulnerable Vulnerable Not in release
Show less packages

CVE-2018-21015

Medium priority
Vulnerable

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication =...

2 affected packages

gpac, ccextractor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Vulnerable Vulnerable
ccextractor Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2019-13618

Medium priority
Vulnerable

In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-12483

Medium priority
Vulnerable

An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-12482

Medium priority
Vulnerable

An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-12481

Medium priority
Vulnerable

An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-11222

Medium priority
Vulnerable

gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-11221

Medium priority
Vulnerable

GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not in release Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-20763

Medium priority

Some fixes available 4 of 6

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

1 affected package

gpac

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Not affected Not affected Fixed
Show less packages